CVE-2024-21877
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Aug 12, 2024
Updated: Aug 23, 2024
CWE ID 22
Summary
CVE-2024-21877 is a path traversal vulnerability affecting Enphase IQ Gateway, formerly known as Envoy, from versions 4.x to 8.0 and below 8.2.4225. Hackers can exploit this issue by manipulating a url parameter, which allows them to traverse restricted directories and perform file manipulation. Authentication is required to access the endpoint, increasing the risk of unauthorized access and potential data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share